WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts (TLP:CLEAR) Supply Chain Compromise of Third-Party GitHub Action, CVE-2025-30066
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

(TLP:CLEAR) Supply Chain Compromise of Third-Party GitHub Action, CVE-2025-30066

TLP:CLEAR

Author: Chase Snow

Created: Thursday, March 20, 2025 - 15:06

Categories: Cybersecurity, Federal & State Resources, Security Preparedness

Summary: A popular third-party GitHub Action, tj-actions/changed-files (tracked as CVE-2025-30066), was recently compromised. This GitHub Action is designed to detect which files have changed in a pull request or commit. The supply chain compromise allows for information disclosure of secrets including, but not limited to, valid access keys, GitHub Personal Access Tokens (PATs), npm tokens, and private RSA keys. This has been patched in v46.0.1. 

The compromise of tj-actions/changed-files was potentially due to a similar compromise of another GitHub Action, reviewdog/action-setup@v1 (tracked as CVE-2025-30154), which occurred around the same time.

Analyst Note: WaterISAC suggests members who may be affected to refer to CISA’s recent alert. Users are strongly recommended to implement the recommendations to mitigate this compromise and strengthen security when using third-party actions.

Original Source: https://www.cisa.gov/news-events/alerts/2025/03/18/supply-chain-compromise-third-party-github-action-cve-2025-30066

Additional Reading:

CISA Warns of Active Exploitation in GitHub Action Supply Chain Compromise

Mitigation Recommendations:

  • Security hardening for GitHub Actions
  • tj-actions changed-files through 45.0.7 allows remote attackers to discover secrets by reading actions logs.
  • tj-actions changed-files

Related WaterISAC PIRs: 6, 11

Related Resources

(TLP:CLEAR) Vulnerability Notification – Critical Vulnerability in Fortinet EMS Actively Exploited, CVE-2026-35616

May 29, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) GAO Report: Actions Needed to Address Persistent Cybersecurity Threats to the Water and Wastewater Sector

May 28, 2026 in Cybersecurity, Federal & State Resources, OT-ICS Security

(TLP:CLEAR) FBI Releases Multiple Alerts on Credential Theft and Evolving Ransomware Intrusion Techniques

May 28, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar